[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 21 23:03:56 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b055b5a7 by Moritz Muehlenhoff at 2026-08-22T00:03:08+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2683,35 +2683,35 @@ CVE-2026-32475 (Unrestricted Upload of File with Dangerous Type vulnerability in
 CVE-2026-23501 (Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Imp ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-20359 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20358 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20357 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20327 (A vulnerability in the web-based management interface of Cisco Unified ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20320 (A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20319 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20318 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20317 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20315 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20314 (A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20302 (A vulnerability in the USB driver of Cisco RoomOS could allow an unaut ...)
 	NOT-FOR-US: Cisco
 CVE-2026-20232 (A vulnerability in the web-based management interface of Cisco Industr ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20231 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20177 (A vulnerability in the handling of management plane packets by Cisco I ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20030 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to ...)
 	NOT-FOR-US: IBM
 CVE-2026-19672 (The tarfile module's tar and data  extraction filters created director ...)
@@ -2727,13 +2727,13 @@ CVE-2026-19321 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, a
 CVE-2026-19234 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
 	NOT-FOR-US: IBM
 CVE-2026-19198 (Akaunting 3.1.21 contains an authenticated improper authorization vuln ...)
-	TODO: check
+	NOT-FOR-US: Akaunting
 CVE-2026-18874 (A flaw was found in volsync-addon-controller. This vulnerability allow ...)
 	NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-18848 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
 	NOT-FOR-US: IBM
 CVE-2026-18756 (HumHub Community Edition 1.18.4 contains a reflected cross-site script ...)
-	TODO: check
+	NOT-FOR-US: HumHub
 CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00  ...)
 	NOT-FOR-US: IBM
 CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross- ...)
@@ -4855,7 +4855,7 @@ CVE-2026-47719 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard)
 CVE-2026-47699 (Confidential Containers Guest Components provides guest tools and comp ...)
 	TODO: check
 CVE-2026-41921 (Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-s ...)
-	TODO: check
+	- koha <itp> (bug #702134)
 CVE-2026-27365 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-21584 (This High severity Improper Authorization vulnerability was introduced ...)
@@ -4873,9 +4873,9 @@ CVE-2026-19782 (The WPS Bidouille WordPress plugin before 1.33.5 does not have p
 CVE-2026-19709 (The Membership For WooCommerce WordPress plugin before 3.1.2 does not  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19671 (Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforce ...)
-	TODO: check
+	NOT-FOR-US: Malcolm
 CVE-2026-19670 (Malcolm's nginx Lua role-based access control (RBAC) layer decides whe ...)
-	TODO: check
+	NOT-FOR-US: Malcolm
 CVE-2026-19417 (The KiviCare  WordPress plugin before 4.5.4 does not verify that the r ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19416 (The KiviCare  WordPress plugin before 4.5.4 does not verify that the r ...)
@@ -6032,7 +6032,7 @@ CVE-2026-45116 (MyBB is free and open source forum software. Prior to 1.8.40, th
 CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, the Budd ...)
 	NOT-FOR-US: MyBB
 CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.6 ...)
-	TODO: check
+	NOT-FOR-US: Saleor
 CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in ninenines cow ...)
 	TODO: check
 CVE-2026-34884 (SSRF via set_skywalking_url Tool and GraphQL expression injection vuln ...)
@@ -6157,7 +6157,7 @@ CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of protec
 CVE-2026-18751 (External control of file name or path vulnerability in Citrix WorkSpac ...)
 	NOT-FOR-US: Citrix
 CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the address bar  ...)
-	TODO: check
+	NOT-FOR-US: ArcSearch
 CVE-2026-18392
 	REJECTED
 CVE-2026-17106 (The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ...)
@@ -6203,13 +6203,13 @@ CVE-2026-15585 (Improper Limitation of a Pathname to a Restricted Directory ('Pa
 CVE-2026-12564 (A flaw was found in the AAP Controller's HashiCorp Vault credential pl ...)
 	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2025-9211 (Unescaped stored values in application security page in Otalio Ship Pr ...)
-	TODO: check
+	NOT-FOR-US: Otalio
 CVE-2025-9210 (Missing signature validation in JSON Web Tokens in Otalio Ship Propert ...)
-	TODO: check
+	NOT-FOR-US: Otalio
 CVE-2024-14046 (A security vulnerability has been detected in OpenBoxes up to 0.9.1. T ...)
-	TODO: check
+	NOT-FOR-US: OpenBoxes
 CVE-2024-14045 (A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerab ...)
-	TODO: check
+	NOT-FOR-US: OpenBoxes
 CVE-2026-XXXX [sogo issues from 5.12.10]
 	- sogo 5.12.10-1
 	NOTE: https://www.sogo.nu/news/2026/sogo-v51210-released.html
@@ -6469,13 +6469,13 @@ CVE-2026-47686 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, h
 CVE-2026-47683 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the buf ...)
 	NOT-FOR-US: Node.js vm2
 CVE-2026-45791 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-45790 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
-	TODO: check
+	NOT-FOR-US: Dokploy
 CVE-2026-44846 (JumpServer is an open source bastion host and an operation and mainten ...)
-	TODO: check
+	NOT-FOR-US: JumpServer
 CVE-2026-44845 (JumpServer is an open source bastion host and an operation and mainten ...)
-	TODO: check
+	NOT-FOR-US: JumpServer
 CVE-2026-43795 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2026-43794 (A memory corruption issue was addressed with improved memory handling. ...)
@@ -6491,9 +6491,9 @@ CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts bei
 CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability in the st ...)
 	NOT-FOR-US: OpenEMR
 CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
-	TODO: check
+	NOT-FOR-US: SteelSeries GG
 CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ...)
-	TODO: check
+	NOT-FOR-US: SteelSeries GG
 CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the Velocity  ...)
 	TODO: check
 CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, automat ...)
@@ -6856,7 +6856,7 @@ CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent dir
 	[trixie] - node-extract-zip <no-dsa> (Minor issue)
 	NOTE: https://github.com/max-mapper/extract-zip/pull/160
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
-	TODO: check
+	NOT-FOR-US: Kong Mesh
 CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially vulnerabl ...)
 	NOT-FOR-US: HP
 CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software Technologies  ...)
@@ -6898,15 +6898,15 @@ CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin (
 CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: ev ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve generative  ...)
-	TODO: check
+	NOT-FOR-US: UpTrain
 CVE-2025-27771 (UpTrain is an open-source platform to evaluate and improve generative  ...)
-	TODO: check
+	NOT-FOR-US: UpTrain
 CVE-2025-27770 (UpTrain is an open-source platform to evaluate and improve generative  ...)
-	TODO: check
+	NOT-FOR-US: UpTrain
 CVE-2025-27621 (UpTrain is an open-source platform to evaluate and improve generative  ...)
-	TODO: check
+	NOT-FOR-US: UpTrain
 CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
 	- antiword <unfixed> (bug #1144645)
 	[trixie] - antiword <postponed> (Revisit when fixed upstream)
@@ -14769,23 +14769,23 @@ CVE-2026-14478 (A maliciously created executable, when executed on the victim's
 CVE-2026-11325 (Description    Cloudflare was recently notified by external researcher ...)
 	TODO: check
 CVE-2025-59327 (In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59326 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforc ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59325 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encryp ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59324 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to proper ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59323 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to valida ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59322 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to proper ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59321 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a defa ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59320 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 s ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59319 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certif ...)
-	TODO: check
+	NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-41771 (An authenticated attacker with low privileges can access an endpoint i ...)
 	TODO: check
 CVE-2025-41770 (An unauthenticated denial-of-service vulnerability in the device's PLC ...)
@@ -16869,7 +16869,7 @@ CVE-2026-20780 (Uncontrolled resource consumption for some Intel(R) PROSet/Wirel
 CVE-2026-20778 (Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for ...)
 	NOT-FOR-US: Intel
 CVE-2026-20776 (Improper conditions check for some Intel(R) PROSet/Wireless WiFi Softw ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20775 (Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust  ...)
 	NOT-FOR-US: Intel
 CVE-2026-20770 (Protection mechanism failure for some Cluster Management Toolkit for K ...)
@@ -17070,13 +17070,13 @@ CVE-2026-0465 (A Use\u2011After\u2011Free (UAF) vulnerability in the AMD Ryzen\u
 CVE-2025-8087 (A DLL hijacking vulnerability in AMD Power Design Manager could allow  ...)
 	NOT-FOR-US: AMD
 CVE-2025-61970 (Weak permissions in the Vitis\u2122 Unified installation path on local ...)
-	TODO: check
+	NOT-FOR-US: AMD
 CVE-2025-54512 (A DLL hijacking vulnerability within the AMD Ryzen Master installation ...)
 	NOT-FOR-US: AMD
 CVE-2025-48506 (Uncontrolled search paths in Vitis\u2122 Unified installation path on  ...)
 	NOT-FOR-US: AMD
 CVE-2025-48505 (Weak permissions in the Vitis\u2122 Unified installation path on local ...)
-	TODO: check
+	NOT-FOR-US: AMD
 CVE-2025-35987 (Omission of security-relevant information for some Intel(R) Software G ...)
 	TODO: check
 CVE-2025-31356 (Insufficient verification of data authenticity for some Intel(R) Trust ...)
@@ -17086,7 +17086,7 @@ CVE-2025-31114 (Fooocus is an image generating software. In versions 2.5.5 and p
 CVE-2025-0046 (Incorrect directory permissions could allow a local user to escalate t ...)
 	TODO: check
 CVE-2025-0041 (Uncontrolled search paths in the Vitis\u2122 Embedded Single File Down ...)
-	TODO: check
+	NOT-FOR-US: AMD
 CVE-2023-54374
 	REJECTED
 CVE-2023-54373



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b055b5a76819c6d2d225330ab95e212a9874eca7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b055b5a76819c6d2d225330ab95e212a9874eca7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/2bdbe2ed/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list